It appears that Nintendo has been silently working behind the scenes to keep 3DS, Wii U, and Switch players safe from a “severe” exploit while they are gaming online.
The recently-uncovered exploit, titled “ENLBufferPwn”, allows hackers to remotely execute code in a victim’s 3DS/Wii U/Switch system by simply sharing an online game session in first party 3DS, Wii U and Switch games. This essentially allows a “full console takeover” where a hacker can steal sensitive information or take audio/video recordings from the victim’s 3DS/Wii U/Switch system.
This security vulnerability is considered so serious that it has been rated with a “critical score” of 9.8/10 in the Common Vulnerability Scoring System Version (CVSS). It was apparently reported via Nintendo’s HackerOne program sometime in 2021/2022 by @Pablomf6, who received a $1000 “bounty” as a reward for doing so.
Since then, it is understood that the following titles are affected by the exploit, with Nintendo attempting to patch it out (list courtesy of PabloMK7, Rambo6Glaz, and Fishguy6564):
It is unknown if any other Nintendo-developed games are affected by the issue. We’ll report back if we hear more in the future.
LEGO Group has announced another LEGO videogame console. The SEGA Genesis / Mega Drive is…
Nintendo and LEGO have announced another Animal Crossing set. The new set is called the Timmy…
The Pokemon Company has started a new 7* Tera Raid event for Pokemon Scarlet And Violet.…
Over a decade after the original game's release, Nintendo has released a new update for…
The Taiwan Digital Game Rating Committee has published another rating for an unannounced Switch 2…
Publisher Atari and developer Digital Eclipse have released a new update for Mortal Kombat: Legacy…